Stories
Slash Boxes
Comments
NOTE: use Perl; is on undef hiatus. You can read content, but you can't post it. More info will be forthcoming forthcomingly.

All the Perl that's Practical to Extract and Report

use Perl Log In

Log In

[ Create a new account ]

schwern (1528)

schwern
  (email not shown publicly)
http://schwern.net/
AOL IM: MichaelSchwern (Add Buddy, Send Message)
Jabber: schwern@gmail.com

Schwern can destroy CPAN at his whim.

Journal of schwern (1528)

Monday May 19, 2003
05:34 PM

support@microsoft.com

[ #12315 ]

Never in the darkest days of Klez was it this bad. Overnight I got 300+ virus mails from "support@microsoft.com". THREE HUNDRED! Fortunately, SpamAssassin was ready.

For anyone else caught by this, here's my rules:

header   FROM_SUPPORTMICROSOFT  From =~ /\bsupport\@microsoft\.com\b/
describe FROM_SUPPORTMICROSOFT  From: support@microsoft.com (virus)
score    FROM_SUPPORTMICROSOFT  1.5

rawbody  BODY_SUPPORTMICROSOFT  /^All information is in the attached file\.\s*$/m
describe BODY_SUPPORTMICROSOFT  support@microsoft.com virus body
score    BODY_SUPPORTMICROSOFT  1.5

meta     SUPPORTMICROSOFT_VIRUS FROM_SUPPORTMICROSOFT && BODY_SUPPORTMICROSOFT
describe SUPPORTMICROSOFT_VIRUS support@microsoft.com virus
score    SUPPORTMICROSOFT_VIRUS 6.5

The Fine Print: The following comments are owned by whoever posted them. We are not responsible for them in any way.
 Full
 Abbreviated
 Hidden
More | Login | Reply
Loading... please wait.
  • This is my procmail recipie:

    # If it's support@microsoft.com, just toss the damn thing
    :0
    * ^From:.*support\@microsoft\.com
    /dev/null

    • How appropriate that you're sending M$ support to /dev/null, because that's where it comes from as well.

      {grin}

      --
      • Randal L. Schwartz
      • Stonehenge
  • Looks like my regularly updated clamav caught all of mine. I've yet to have a virus sneak through, and I plug it into qpsmtpd so it all just happens at SMTP time, sending a 55x back so I don't even have to save the virus to disk.